Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.9 CVE-2017-13863 An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle at… Iphone Os 11.0+ Fix from $1,6002018-04-03 CRITICAL 9.8 CVE-2018-9127 Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, unde… Botan after 2.4.0 Fix from $2,3002018-04-02 MEDIUM 5.9 CVE-2015-4954 IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attac… Bigfix Remote Control Patch available Fix from $1,6002018-03-27 HIGH 7.5 CVE-2018-5462 Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to… Intellispace Portal Mitigation only Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-5464 Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain una… Intellispace Portal Mitigation only Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-5466 Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain un… Intellispace Portal Mitigation only Fix from $1,9502018-03-26 HIGH 7.4 CVE-2018-8970 The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a ze… Libressl Patch available Fix from $1,9502018-03-24 HIGH 7.5 CVE-2018-5502 On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. … Big Ip Access Policy Manager 13.1.0.4+ Fix from $1,9502018-03-22 MEDIUM 6.5 CVE-2018-6219 An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain ty… Email Encryption Gateway No fix yet Fix from $1,6002018-03-15 HIGH 8.1 CVE-2018-6221EPSS 6% An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an u… Email Encryption Gateway Patch available Fix from $1,9502018-03-15 HIGH 8.1 CVE-2018-1000096 brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificat… Tiny Json Http after 7.0.0 Fix from $1,9502018-03-13 HIGH 8.1 CVE-2016-9952 The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, ma… Curl after 7.51.0 Fix from $1,9502018-03-12 HIGH 8.1 CVE-2017-2667 Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by defau… Satellite 0.10.0+ Fix from $1,9502018-03-12 HIGH 7.5 CVE-2017-18227 TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature. Webtitan Gateway Mitigation only Fix from $1,9502018-03-12 HIGH 8.8 CVE-2018-8059 The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Mi… Portus Mitigation only Fix from $1,9502018-03-11 HIGH 7.5 CVE-2018-7234 A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system … Mps110 1 Firmware 3.29.67+ Fix from $1,9502018-03-09 HIGH 8.8 CVE-2017-7429 The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authen… Edirectory after 8.8.8 Fix from $1,9502018-03-02 MEDIUM 5.9 CVE-2012-6709 ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation. Elinks Patch available Fix from $1,6002018-02-23 MEDIUM 5.9 CVE-2018-0518 LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers an… Line after 7.15 Fix from $1,6002018-02-23 MEDIUM 5.9 CVE-2017-17455 Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to intera… Mahara 16.10.7 / 17.04.5+ Fix from $1,6002018-02-20 CRITICAL 9.8 CVE-2017-17301 Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C0… Ar120 S Firmware Mitigation only Fix from $2,3002018-02-15 HIGH 7.5 CVE-2017-15341 Huawei AR3200 V200R008C20, V200R008C30, TE40 V600R006C00, TE50 V600R006C00, TE60 V600R006C00 have a denial of service vulnerability. The software dec… Ar3200 Firmware Mitigation only Fix from $1,9502018-02-15 MEDIUM 5.9 CVE-2017-12721 An Improper Certificate Validation issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. T… Medfusion 4000 Wireless Syringe Infusion Pump Mitigation only Fix from $1,6002018-02-15 MEDIUM 5.9 CVE-2017-9968 A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certifica… Igss Mobile after 3.01 Fix from $1,6002018-02-12 HIGH 8.1 CVE-2018-6827 VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and o… Vobot Firmware 0.99.30+ Fix from $1,9502018-02-09 MEDIUM 6.5 CVE-2018-6374 The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL C… Desktop Linux Client 5.2r9.2 / 5.3r4.2+ Fix from $1,6002018-01-31 MEDIUM 5.9 CVE-2017-15698 When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly h… Tomcat Native after 1.2.14 Fix from $1,6002018-01-31 MEDIUM 5.9 CVE-2017-1000396 Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectl… Jenkins after 2.83 Fix from $1,6002018-01-26 MEDIUM 5.3 CVE-2017-1000417 MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509… Matrixssl Mitigation only Fix from $1,6002018-01-22 HIGH 8.1 CVE-2018-5761 A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubr… Cdm after 4.0.4 Fix from $1,9502018-01-22